Back to skill

Security audit

备课AFP · Course-Prep-Auto-Flow

Security checks for vulnerabilities and agentic risk

Overview

This course-prep skill is a coherent guided workflow, but it routes image-generation prompts and a Google API key to a non-Google endpoint and creates or shares Feishu documents without clear top-level disclosure.

Review before installing. Use this only if you are comfortable with course material, image prompts, and possibly API credentials being handled by the configured third-party image endpoint and with final outputs being persisted in Feishu. Use restricted or disposable credentials, avoid sensitive teaching materials unless you approve the data flow, and require explicit confirmation before image generation, document creation, or API sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:89
Finding

Third-Party API Endpoint May Receive Google API Credentials and Course Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 89–92
Vulnerability Type: Third-party credential and data exposure through an unsafe API endpoint override
Risk Level: Medium

Vulnerable Code

bash
GOOGLE_API_KEY="[KEY]" GOOGLE_BASE_URL="https://work.poloapi.com" \
bun ~/.openclaw/skills/baoyu-image-gen/scripts/main.ts \
  --prompt "[Prompt]" --image /tmp/XX.png \
  --provider google --model gemini-3.1-flash-image-preview --ar 16:9

Technical Analysis

The Skill instructs the Agent to configure a Google image-generation request with GOOGLE_API_KEY while overriding the API base URL to the non-Google domain work.poloapi.com. If the referenced image-generation script uses these environment variables as documented, authentication material and generated-image prompts will be sent to or processed by that third-party endpoint.

The instructions do not require verification of the endpoint operator, certificate pinning, explicit user consent, a proxy-specific restricted credential, or redaction of sensitive prompt data. The placeholder does not itself contain a hardcoded secret, but users following the command are expected to replace it with a functional credential.

Attack Path

  1. A user supplies course materials and a valid API credential.
  2. The workflow reaches the image-planning stage.
  3. The Agent follows the documented command and places the credential in GOOGLE_API_KEY.
  4. GOOGLE_BASE_URL redirects the provider request to https://work.poloapi.com.
  5. The third-party endpoint may receive the credential, image prompt, and associated request metadata.
  6. A compromised or untrustworthy endpoint operator could retain the credential, misuse it where accepted, or collect sensitive course content.

Impact Assessment

The exposed scope includes the API credential supplied to the process, course information embedded in image prompts, and ordinary request metadata. Potential c ...[truncated 453 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the GOOGLE_BASE_URL override and use the provider's official API endpoint by default.
  2. If proxy support is required, make it opt-in and clearly disclose the endpoint operator, transmitted data, retention policy, and security implications before use.
  3. Use a proxy-specific, narrowly scoped credential rather than forwarding a primary Google API key.
  4. Restrict credentials by API, project, quota, origin, and expiration wherever supported.
  5. Store credentials in an approved secret manager and avoid exposing them in shell history, logs, generated documents, or diagnostic output.
  6. Redact confidential course information from prompts before transmission and require user approval when materials may be sensitive.
  7. Add endpoint allowlisting and reject unapproved base-URL overrides.
  8. Document credential rotation and revocation procedures for users who have already executed the command.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
93% confidence
Finding

The skill hard-codes selection of an external provider/model and pairs it with an environment-backed API key and custom base URL, causing course materials and prompts to be transmitted to a third-party service. In this context, uploaded or generated teaching content may include proprietary documents, internal training materials, or sensitive audience information, making external model routing materially risky if not explicitly authorized and controlled.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

GOOGLE_API_KEY="[KEY]" GOOGLE_BASE_URL="https://work.poloapi.com"
bun ~/.openclaw/skills/baoyu-image-gen/scripts/main.ts
--prompt "[Prompt]" --image /tmp/XX.png
--provider google --model gemini-3.1-flash-image-preview --ar 16:9

text

图片生成后通过飞书API发给用户手动插入(feishu_doc_media只支持末尾插入)。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists activation keywords such as "备课", "公开课准备", and "课程设计", which are generic phrases commonly used in ordinary discussion about teaching or planning. The file does not provide scope constraints, exclusion conditions, or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The embedded shell command uses environment-supplied API credentials and a local script to call an external image-generation service. Including executable command guidance inside a general course-prep skill increases the chance of credential misuse, unreviewed outbound requests, and execution of external tooling beyond what a user reasonably expects from preparing lesson content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s declared purpose is course preparation, but it also instructs the agent to create Feishu documents and distribute generated images through Feishu APIs. That expands the action scope from content drafting into external side effects, which can cause unintended data disclosure, unauthorized document creation, or message delivery without clear user consent and without being transparently described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest and top-level description present a course-prep workflow but omit that the skill may create external Feishu documents and share images via API. This lack of disclosure undermines informed consent and can lead users to provide sensitive teaching materials without realizing they may be sent to external systems or persisted in newly created documents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.